SPF, DKIM and DMARC Explained Simply, With Setup Steps
Anyone can send an email that pretends to come from your domain unless you set up three DNS records: SPF, DKIM and DMARC. This guide explains what each one does and how to set them up safely.
What are SPF, DKIM and DMARC, and how do I set them up?
SPF, DKIM and DMARC setup protects your domain from fake emails. SPF lists the servers allowed to send your email, DKIM adds a digital signature to each message, and DMARC tells receiving servers what to do when a message fails these checks. You add all three as DNS records, start DMARC in monitor mode, then move to a strict policy.
Key takeaways
- SPF says who may send; DKIM proves the message was not changed; DMARC sets the rule.
- All three are DNS records you add at your domain's DNS provider.
- List every service that sends email for you before you start.
- Start DMARC at p=none, read reports, then move to quarantine and reject.
- Gmail and Yahoo now require authentication for bulk senders.
- Wrong records can block your own emails, so change them carefully.
What are SPF, DKIM and DMARC?
SPF, DKIM and DMARC are three email authentication standards that work together. They help receiving mail servers check that an email using your domain really came from you.
| Record | Question it answers | Where it lives |
|---|---|---|
| SPF | Is this server allowed to send for this domain? | TXT record on yourdomain.com |
| DKIM | Was this message signed by the domain and not changed? | TXT or CNAME at selector._domainkey.yourdomain.com |
| DMARC | What should happen if checks fail, and who gets reports? | TXT record at _dmarc.yourdomain.com |
Why does email security with SPF, DKIM and DMARC matter for a business?
Without these records, scammers can send emails that look like they come from your company, and your real emails are more likely to land in spam. Setting them up protects customers, staff and your sender reputation.
- Stops fake invoices and payment change requests sent in your name
- Protects customers from fake order, refund or KYC emails
- Improves inbox delivery for quotes, invoices and newsletters
- Meets the sender rules that Gmail and Yahoo started enforcing in 2024 for bulk senders
- Gives you DMARC reports that show who is sending email using your domain
Step 1: List every service that sends email for your domain
Before adding any record, list every system that sends email using your domain. If you miss one, its emails may fail once DMARC becomes strict.
- Main mailbox provider, such as Google Workspace, Microsoft 365 or Zoho Mail
- Website contact forms and WooCommerce or Shopify order emails
- Email marketing tools such as Mailchimp, Brevo or similar
- CRM, helpdesk and invoicing tools that send in your name
- Transactional email services used by your app, such as Amazon SES or SendGrid
- Hosting server mail (cPanel) if forms send directly from the server
- Any agency or vendor that sends campaigns for you
This list also helps your data security planning, because each tool may hold customer email addresses.
How to set up SPF, DKIM and DMARC step by step
Set up SPF first, then DKIM for each sending service, then DMARC in monitor mode. Check each step with a test email before moving on.
- 1
Create one SPF record
Add a single TXT record starting with v=spf1 that includes each sending service, for example include entries given by your providers, ending with ~all or -all. Never create two SPF records.
- 2
Stay under the SPF lookup limit
SPF allows up to 10 DNS lookups. Too many include entries cause SPF to fail. Remove services you no longer use.
- 3
Turn on DKIM in each service
In Google Workspace, Microsoft 365, Zoho and marketing tools, generate DKIM keys and add the given DNS records. Then click verify or start authentication.
- 4
Add a DMARC record in monitor mode
Create a TXT record at _dmarc with v=DMARC1; p=none; and a rua address to receive aggregate reports.
- 5
Send test emails
Send to a Gmail account and use Show original to check SPF, DKIM and DMARC all show PASS.
- 6
Read DMARC reports for a few weeks
Use a DMARC report viewer to see which sources pass and fail. Fix legitimate senders that fail.
- 7
Move to quarantine
Change the policy to p=quarantine, at first for a percentage of mail if your tool supports it.
- 8
Move to reject
When reports are clean, set p=reject so fake emails are refused.
DMARC policy: none vs quarantine vs reject, which should I use?
Start with p=none to collect reports without affecting mail, then move to p=quarantine, and finally p=reject for full protection. Jumping straight to reject can block your own invoices or form emails.
| Policy | What happens to failing mail | When to use |
|---|---|---|
| p=none | Delivered as normal; reports sent to you | First weeks, while you find all senders |
| p=quarantine | Usually sent to spam or junk | After main senders pass |
| p=reject | Refused by the receiving server | When reports show only known, passing senders |
Strict policy (reject)
- Strongest protection against spoofing
- Clear signal to mailbox providers
- Protects brand trust
Risk if rushed
- Forgotten senders get blocked
- Forwarded mail can fail in some cases
- Needs regular report checks after changes
Common SPF, DKIM and DMARC mistakes to avoid
The most common mistakes are having two SPF records, going over the SPF lookup limit, forgetting a sending service, and never reading DMARC reports. Each one weakens protection or blocks real mail.
- Two separate SPF TXT records instead of one combined record
- Using +all in SPF, which allows anyone to send
- DKIM set up only for the main mailbox, not for the marketing or CRM tool
- Website forms sending from a Gmail address through your server, which fails DMARC
- DMARC report address with a typo, so no reports arrive
- Leaving p=none for years and thinking the domain is protected
- Not protecting unused domains; add SPF -all and DMARC reject to domains that never send mail
For website forms, use SMTP through your mail provider or a transactional email service instead of the server's default mail function. If your website is also showing signs of misuse, check our website hacked guide.
Beyond DMARC: other email security steps
SPF, DKIM and DMARC protect your domain from being faked, but you also need strong logins, two-step login, safe forwarding rules and staff training to protect your mailboxes.
- Turn on two-step login for every mailbox; see our password security policy guide
- Check for unknown forwarding rules, a common sign of a hacked mailbox
- Turn on built-in phishing and malware filters in Google Workspace or Microsoft 365
- Use MTA-STS and TLS reporting for extra transport protection if your provider supports it
- Consider BIMI to show your logo in some inboxes once DMARC is at quarantine or reject
- Remove mailboxes of staff who have left, or convert them to shared mailboxes with controlled access
Our email security setup service
We review your domain, list all senders, set up SPF, DKIM and DMARC, read the reports and move you safely to a strict policy. Most domains reach a strict policy within a few weeks.
- Number of domains and subdomains that send mail
- Number of sending services and tools
- Mailbox provider: Google Workspace, Microsoft 365, Zoho or other
- Website and app email setup
- Ongoing DMARC report monitoring
You get a clear quote after a free call. Our parent team, Shivah Web Tech, has 11+ years of experience setting up business email and websites. This service is also part of our cybersecurity consulting work. Contact us to start.
Related Pages
Phishing Training
Teach your team to spot fake emails, calls and WhatsApp scams.
Data Security
Protect customer records, files and business data.
Security Consulting
Practical security plans, policies and advice for owners.
Password Policy Guide
A simple password and two-step login policy your team will follow.
Frequently Asked Questions
Do I need SPF, DKIM and DMARC for a small business?
Yes. These records are free to add and protect your domain from being used in fake emails. They also help your quotes, invoices and replies reach the inbox. Gmail and Yahoo now expect authentication from senders, so even small businesses benefit from setting all three up.
Why are my emails going to spam even with SPF set up?
SPF alone is often not enough. You may be missing DKIM or DMARC, your SPF may have too many lookups, or the sending service may not be aligned with your domain. Content, sending volume and past complaints also matter. Check the email headers to see which checks pass or fail.
Can DMARC block my own emails?
Yes, if you set a strict policy before all your sending services pass SPF or DKIM with alignment. This is why you start with p=none, read reports, fix every real sender and only then move to quarantine and reject. Done in stages, the risk is low.
How long does it take for SPF, DKIM and DMARC to work?
DNS changes usually take effect within minutes to a few hours, depending on the record's TTL setting. Moving DMARC from monitor mode to reject safely takes longer, often a few weeks, because you need time to collect reports and fix legitimate senders.
What is a DMARC report and who should read it?
A DMARC aggregate report is a daily XML file sent by mailbox providers. It lists which servers sent email using your domain and whether they passed checks. The raw files are hard to read, so most businesses use a DMARC report tool or ask their IT partner to review them.
Do I need DMARC on a domain that does not send email?
Yes. Unused or parked domains are easy targets for spoofing. Add an SPF record with -all, which means no server may send, and a DMARC record with p=reject. This tells receivers to refuse any email that claims to come from that domain.
How do I check if my domain has SPF, DKIM and DMARC?
Send an email from your domain to a Gmail account, open it, click the three dots and choose Show original. Gmail shows whether SPF, DKIM and DMARC passed. You can also look up your domain's TXT records with a free DNS lookup tool to see the exact SPF and DMARC records.
Will DMARC stop all phishing emails to my staff?
No. Your DMARC record protects your own domain from being faked. It does not stop scammers who use look-alike domains, free email accounts or hacked accounts at other companies. Your mailbox filters and staff awareness training are still needed to catch these messages.
Which is more important, SPF or DKIM?
Both matter, and DMARC needs at least one of them to pass with alignment. DKIM is often more reliable because it survives forwarding, while SPF can break when mail is forwarded. Setting up both gives the best protection and delivery.
Talk to our team today
Call or WhatsApp +91 85808 92163. We reply fast, Monday to Friday.